No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 24 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cap-go
Cap-go cap-go |
|
| Vendors & Products |
Cap-go
Cap-go cap-go |
Mon, 22 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 20 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Supabase - Unauthenticated Cross-Tenant Billing Log Tampering via public.record_build_time RPC | Capgo - Unauthenticated Cross-Tenant Billing Log Tampering via public.record_build_time RPC |
Fri, 19 Jun 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and callable with only the public Supabase publishable (sb_publishable_*) anon key. An unauthenticated attacker can insert rows into public.build_logs for arbitrary organizations and, because the function uses ON CONFLICT (build_id, org_id) DO UPDATE, can overwrite existing usage/billing records by reusing the same build_id for a target org. This enables cross-tenant tampering of billing build logs and financial-impact denial of service by inflating billable build time. | |
| Title | Supabase - Unauthenticated Cross-Tenant Billing Log Tampering via public.record_build_time RPC | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-22T14:02:40.698Z
Reserved: 2026-06-18T15:57:20.434Z
Link: CVE-2026-56082
Updated: 2026-06-22T14:02:36.403Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T20:30:04Z